Preserve continue URL on auth error re-login

Failed OIDC, magic-link, and SAML sign-ins sent users to /auth/error
without the post-login destination, so Sign in dropped OAuth flows
and deep links. Propagate a validated continue query through auth
error redirects, recover it from OIDC state when the IdP denies or
cancels login, and forward it from AuthErrorPage to /auth/login.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: Bryan FRIMIN <bryan@frimin.fr>
This commit is contained in:
Cursor Agent
2026-07-27 10:27:38 +00:00
committed by Bryan Frimin
parent 428d28fade
commit 9abea50507
8 changed files with 205 additions and 29 deletions

View File

@@ -670,6 +670,15 @@ func (s AuthService) GetMagicLinkEmail(ctx context.Context, tokenString string)
return payload.Data.Email, nil
}
func (s AuthService) MagicLinkContinueFromToken(tokenString string) (*string, error) {
payload, err := statelesstoken.ValidateTokenAllowExpired[MagicLinkData](s.tokenSecret, TokenTypeMagicLink, tokenString)
if err != nil {
return nil, err
}
return payload.Data.Continue, nil
}
func (s AuthService) OpenSessionWithMagicLink(ctx context.Context, tokenString string) (*coredata.Identity, *coredata.Session, *string, error) {
var (
now = time.Now()